Sample code for 30+ languages & platforms
Objective-C

SOAP WS-Security UsernameToken

See more XML Examples

Demonstrates how to add a UsernameToken with the WSS SOAP Message Security header.

Note: This example requires Chilkat v9.5.0.66 or later.

Chilkat Objective-C Downloads

Objective-C
#import <CkoXml.h>
#import <NSString.h>
#import <CkoPrng.h>
#import <CkoBinData.h>
#import <CkoDateTime.h>
#import <CkoCrypt2.h>

//  This example requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  An HTTP SOAP request is an HTTP request where the SOAP XML composes the body.
//  This example demonstrates how to add a WS-Security header such as the following:
//  
//  <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="SecurityToken-6138db82-5a4c-4bf7-915f-af7a10d9ae96">
//    <wsse:Username>user</wsse:Username>
//    <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">CBb7a2itQDgxVkqYnFtggUxtuqk=</wsse:Password>
//    <wsse:Nonce>5ABcqPZWb6ImI2E6tob8MQ==</wsse:Nonce>
//    <wsu:Created>2010-06-08T07:26:50Z</wsu:Created>
//  </wsse:UsernameToken>
//  

//  First build some simple SOAP XML that has some header and body.
CkoXml *xml = [[CkoXml alloc] init];
xml.Tag = @"env:Envelope";
[xml AddAttribute: @"xmlns:env" value: @"http://www.w3.org/2003/05/soap-envelope"];
[xml UpdateAttrAt: @"env:Header|n:alertcontrol" autoCreate: YES attrName: @"xmlns:n" attrValue: @"http://example.org/alertcontrol"];
[xml UpdateChildContent: @"env:Header|n:alertcontrol|n:priority" value: @"1"];
[xml UpdateChildContent: @"env:Header|n:alertcontrol|n:expires" value: @"2001-06-22T14:00:00-05:00"];
[xml UpdateAttrAt: @"env:Body|m:alert" autoCreate: YES attrName: @"xmlns:m" attrValue: @"http://example.org/alert"];
[xml UpdateChildContent: @"env:Body|m:alert|m:msg" value: @"Pick up Mary at school at 2pm"];
NSLog(@"%@",[xml GetXml]);
NSLog(@"%@",@"----");

//  The following SOAP XML is built:

//  	<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
//  	 <env:Header>
//  	  <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
//  	   <n:priority>1</n:priority>
//  	   <n:expires>2001-06-22T14:00:00-05:00</n:expires>
//  	  </n:alertcontrol>
//  	 </env:Header>
//  	 <env:Body>
//  	  <m:alert xmlns:m="http://example.org/alert">
//  	   <m:msg>Pick up Mary at school at 2pm</m:msg>
//  	  </m:alert>
//  	 </env:Body>
//  	</env:Envelope>
//  

//  Now build the WSSE XML housing that we'll insert into the above SOAP XML at the end.

//  	<wsse:Security>
//  	  <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
//  	    <wsse:Username>USERNAME</wsse:Username>
//  	    <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
//  	    <wsse:Nonce>NONCE</wsse:Nonce>
//  	    <wsu:Created>CREATED</wsu:Created>
//  	  </wsse:UsernameToken>
//  	</wsse:Security>

CkoXml *wsse = [[CkoXml alloc] init];
wsse.Tag = @"wsse:Security";
[wsse UpdateAttrAt: @"wsse:UsernameToken" autoCreate: YES attrName: @"xmlns:wsu" attrValue: @"http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd"];
[wsse UpdateAttrAt: @"wsse:UsernameToken" autoCreate: YES attrName: @"wsu:Id" attrValue: @"WSU_ID"];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsse:Username" value: @"USERNAME"];
[wsse UpdateAttrAt: @"wsse:UsernameToken|wsse:Password" autoCreate: YES attrName: @"Type" attrValue: @"http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest"];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsse:Password" value: @"PASSWORD_DIGEST"];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsse:Nonce" value: @"NONCE"];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsu:Created" value: @"CREATED"];
NSLog(@"%@",[wsse GetXml]);
NSLog(@"%@",@"----");

//  Insert the wsse:Security XML into the existing SOAP header:
CkoXml *xHeader = [xml GetChildWithTag: @"env:Header"];
[xHeader AddChildTree: wsse];

//  Now show the SOAP XML with the wsse:Security header added:
NSLog(@"%@",[xml GetXml]);
NSLog(@"%@",@"----");

//  Now our XML looks like this:
//  	<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
//  	    <env:Header>
//  	        <n:alertcontrol xmlns:n="http://example.org/alertcontrol">
//  	            <n:priority>1</n:priority>
//  	            <n:expires>2001-06-22T14:00:00-05:00</n:expires>
//  	        </n:alertcontrol>
//  	        <wsse:Security>
//  	            <wsse:UsernameToken xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" wsu:Id="WSU_ID">
//  	                <wsse:Username>USERNAME</wsse:Username>
//  	                <wsse:Password Type="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest">PASSWORD_DIGEST</wsse:Password>
//  	                <wsse:Nonce>NONCE</wsse:Nonce>
//  	                <wsu:Created>CREATED</wsu:Created>
//  	            </wsse:UsernameToken>
//  	        </wsse:Security>
//  	    </env:Header>
//  	    <env:Body>
//  	        <m:alert xmlns:m="http://example.org/alert">
//  	            <m:msg>Pick up Mary at school at 2pm</m:msg>
//  	        </m:alert>
//  	    </env:Body>
//  	</env:Envelope>
//  

//  -----------------------------------------------------
//  Now let's fill-in-the-blanks with actual information...
//  -----------------------------------------------------

NSString *wsu_id = @"Example-1";
[wsse UpdateAttrAt: @"wsse:UsernameToken" autoCreate: YES attrName: @"wsu:Id" attrValue: wsu_id];

NSString *password = @"password";
NSString *username = @"user";
[wsse UpdateChildContent: @"wsse:UsernameToken|wsse:Username" value: username];

//  The nonce should be 16 random bytes.
CkoPrng *prng = [[CkoPrng alloc] init];
CkoBinData *bd = [[CkoBinData alloc] init];
//  Generate 16 random bytes into bd.
//  Note: The GenRandomBd method is added in Chilkat v9.5.0.66
[prng GenRandomBd: [NSNumber numberWithInt: 16] bd: bd];

NSString *nonce = [bd GetEncoded: @"base64"];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsse:Nonce" value: nonce];

//  Get the current date/time in a string with this format: 2010-06-08T07:26:50Z
CkoDateTime *dt = [[CkoDateTime alloc] init];
[dt SetFromCurrentSystemTime];
BOOL bLocal = NO;
NSString *created = [dt GetAsTimestamp: bLocal];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsu:Created" value: created];

//  The password digest is calculated like this:
//  Password_Digest = Base64 ( SHA-1 ( nonce + created + password ) )
[bd AppendString: created charset: @"utf-8"];
[bd AppendString: password charset: @"utf-8"];

CkoCrypt2 *crypt = [[CkoCrypt2 alloc] init];
crypt.HashAlgorithm = @"SHA-1";
crypt.EncodingMode = @"base64";
//  Note: The HashBdENC method is added in Chilkat v9.5.0.66
NSString *passwordDigest = [crypt HashBdENC: bd];
[wsse UpdateChildContent: @"wsse:UsernameToken|wsse:Password" value: passwordDigest];

//  Examine the final SOAP XML with WS-Security header added.
NSLog(@"%@",[xml GetXml]);